generated: '2026-07-15' method: generated source: openapi/xiaomi-galaxy-fds-openapi.yml, openapi/xiaomi-mimo-api-openapi.yml, openapi/xiaomi-open-api-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 23 by_action_class: acting: 14 connected: 9 by_consequence: write: 12 read: 9 safety-critical: 2 human_in_the_loop_required: 2 operations: - path: /{bucketName}/{objectName} method: put operationId: putObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName} method: get operationId: getObject x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{bucketName}/{objectName} method: head operationId: headObject x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{bucketName}/{objectName} method: delete operationId: deleteObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?acl method: put operationId: putObjectAcl x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /{bucketName}/{objectName}?acl method: get operationId: getObjectAcl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{bucketName}/{objectName}?acl method: delete operationId: deleteObjectAcl x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /{bucketName}?delete method: post operationId: deleteMultipleObjects x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?uploads method: post operationId: initiateMultipartUpload x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?partNumber={partNumber}&uploadId={uploadId} method: put operationId: uploadPart x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?uploadId={uploadId} method: post operationId: completeMultipartUpload x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?uploadId={uploadId} method: delete operationId: abortMultipartUpload x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?restore method: post operationId: restoreObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?rename method: post operationId: renameObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?prefetch method: post operationId: prefetchObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{bucketName}/{objectName}?refresh method: post operationId: refreshObject x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/chat/completions method: post operationId: createChatCompletion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/models method: get operationId: listModels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/profile method: get operationId: getUserProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/openidV2 method: get operationId: getUserOpenId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/phoneAndEmail method: get operationId: getUserPhoneAndEmail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/relation method: get operationId: getUserFriendList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /checkPassword method: get operationId: checkUserPassword x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none